Certified Data Privacy Solutions Engineer (CDPSE) Free Sample Questions

20 free sample questions185 in the full practice test

Try simulator

CDPSE Sample Questions

  1. Question 1

    A financial services firm is developing a machine learning model to detect fraudulent transactions. The model requires training on a large dataset of customer transactions from multiple collaborating banks, none of which can share raw data directly due to privacy regulations. The model's accuracy is paramount, and it must be retrained frequently. Which Privacy Enhancing Technology (PET) would be the MOST appropriate solution for this scenario?

    Answer and explanation

    Correct answer: C

    Federated Learning is the ideal solution here. It allows a central model to be trained collaboratively without any of the participating organizations having to expose their raw, sensitive data. Each bank trains a local version of the model on its own data, and only the resulting model weights or updates are sent to a central server for aggregation. This directly addresses the core constraint of not sharing raw data while still enabling the creation of a highly accurate, shared model.

  2. Question 2

    A rapidly scaling technology startup has just secured a new round of funding and plans to expand its operations into the European Union. The company has a flat organizational structure and has handled privacy on an ad-hoc basis so far. What is the MOST effective first step in establishing a formal privacy governance structure to support this growth and ensure compliance?

    Answer and explanation

    Correct answer: D

    For a rapidly scaling startup with a flat structure, the most effective first step is to embed privacy responsibility within the existing organization. Forming a cross-functional committee (involving engineering, product, legal, marketing) and assigning clear privacy champion roles ensures that privacy is integrated into the company's agile culture from the ground up. This approach is more practical and sustainable than immediately imposing a rigid external structure or focusing solely on tools or documentation without clear ownership.

  3. Question 3

    Multiple answers

    A healthcare organization is implementing its data retention policy, which requires that patient electronic health records (EHR) be securely deleted seven years after the patient's last interaction. Which technical controls are ESSENTIAL to enforce this policy effectively? (Select TWO).

    Answer and explanation

    Correct answers: A, C

    Automation is crucial for reliably enforcing a retention schedule at scale. A script that identifies records meeting the deletion criteria (e.g., last interaction date > 7 years) and triggers a secure deletion method like cryptographic erasure is a core technical control.

    To prove compliance and maintain accountability, it is essential to have a secure, tamper-proof log of all data destruction activities. This log serves as evidence that the retention policy is being followed correctly and provides a trail for any future audits or investigations.

  4. Question 4

    A social media company is planning to launch a new feature that uses machine learning to analyze user-uploaded photos and automatically suggest tags based on detected objects, faces, and locations. This processing is not essential for the core service. According to the GDPR, which of the following is the PRIMARY trigger for conducting a Data Protection Impact Assessment (DPIA)?

    Answer and explanation

    Correct answer: C

    Under Article 35 of the GDPR, a DPIA is required when a type of processing, particularly using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. The large-scale processing of special category data (biometrics from faces), combined with location data and innovative use of technology (ML), clearly meets this threshold.

  5. Question 5

    A telehealth provider, 'CareConnect', is developing a new mobile application for remote patient monitoring. The application will collect real-time biometric data (heart rate, blood oxygen) from wearable IoT devices, patient-reported symptoms via a chatbot, and video consultation recordings. CareConnect's primary goals are to ensure patient trust, comply with HIPAA and GDPR, and implement robust Privacy by Design principles.

    The proposed architecture involves the mobile app sending all data directly to a monolithic backend application hosted in a public cloud. This backend processes the data, stores it in a single large database, and serves it to healthcare providers through a web portal. The CISO has raised concerns that this design creates significant privacy risks and lacks necessary controls for data segregation and minimization.

    As the lead privacy engineer, you are tasked with redesigning the architecture to address these concerns. Which of the following architectural approaches BEST integrates Privacy by Design principles for the CareConnect application?

    Answer and explanation

    Correct answer: B

    This approach is the strongest example of Privacy by Design. A microservices architecture inherently promotes data segregation and purpose limitation, as each service only handles the data it needs. Storing data in separate, purpose-built databases (e.g., a time-series DB for biometrics, a document store for chat logs) allows for tailored security controls. The API Gateway acts as a central policy enforcement point, ensuring that only authorized services can access specific data types, thus enforcing the principle of least privilege and data minimization.

  6. Question 6

    True or False: Once personal data has been pseudonymized, it is no longer considered personal data under the GDPR and is exempt from its requirements.

    Answer and explanation

    Correct answer: B

    This is false. The GDPR explicitly defines pseudonymization and considers pseudonymized data to still be personal data, as it can be re-identified with additional information. While pseudonymization is a recommended security measure that can reduce risks and help meet data protection principles, it does not remove the data from the scope of the regulation. Anonymized data, in contrast, is outside the scope of the GDPR.

  7. Question 7

    An e-commerce company uses a third-party cloud provider for hosting its entire infrastructure. The contract includes a Data Processing Agreement (DPA). During a routine audit, it is discovered that the cloud provider has been storing backup snapshots in a geographic region not specified in the DPA, a direct violation of the agreement. What is the MOST critical clause in the DPA that gives the e-commerce company leverage to address this issue?

    Answer and explanation

    Correct answer: C

    The right to audit clause is the most critical contractual tool in this scenario. It grants the data controller (the e-commerce company) the authority to inspect and verify the data processor's (the cloud provider's) compliance with the DPA. This clause provides the legal basis to demand evidence, conduct an audit of the provider's storage locations, and enforce remediation for the contractual breach.

  8. Question 8

    A privacy engineer is reviewing the metrics for the company's data subject access request (DSAR) process. They observe the following trends over the last quarter:

    • The number of incoming requests has increased by 50%.
    • The average time to completion has increased from 15 days to 28 days.
    • The number of requests requiring manual intervention by the legal team has tripled.

    Given these metrics, what is the MOST likely root cause of the performance degradation?

    Answer and explanation

    Correct answer: C

    The combination of increased completion time and a tripling of manual legal interventions strongly points to a failure in the underlying automation. When automated tools cannot find or collate a subject's data from the various production and legacy systems, the process breaks down. This forces manual searches and requires legal review to ensure completeness and handle exceptions, which perfectly explains the observed metrics.

  9. Question 9

    Multiple answers

    A company is implementing a zero-trust security architecture to better protect personal data stored across its hybrid cloud environment. Which of the following are core principles and technologies required for this implementation? (Select THREE).

    Answer and explanation

    Correct answers: B, C, D

    This is a foundational principle of zero trust. Every access request is treated as if it originates from an untrusted network, requiring rigorous verification each time.

    Another core tenet of zero trust is to grant the minimum level of access needed for a task, for the shortest time possible, to minimize the potential impact of a compromised account.

    Zero trust architecture operates on the assumption that a breach is inevitable or has already occurred. Technologies like micro-segmentation are used to create granular zones and policies that prevent an attacker from moving freely within the network.

  10. Question 10

    A multinational corporation wants to transfer personal data of its EU employees to its headquarters in the United States for payroll processing. Following recent legal precedents invalidating previous transfer mechanisms, the company seeks the most legally robust and defensible solution for this recurring transfer. Which option provides the highest level of assurance for this specific scenario?

    Answer and explanation

    Correct answer: D

    For intra-group transfers within a multinational corporation, Binding Corporate Rules (BCRs) are considered the 'gold standard'. While more complex and time-consuming to establish than SCCs, they represent a comprehensive, approved framework for data protection across the entire corporate group. Once approved by a data protection authority, they provide a very strong legal basis for recurring, systematic transfers like payroll processing.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 185 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon